The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · foreign ownership, FOCI, and CMMC scope

CMMC for Foreign-Owned Companies and FOCI: What Actually Applies to You

Last updated:

Last verified: against 32 CFR Part 170, NISPOM, DCSA guidance, DFARS, and related primary sources.

By The Defense Compliance Report Editorial Team · Last verified: August 18, 2026

Educational research — not legal, contractual, export-control, industrial-security, or compliance advice.


If you are researching CMMC for foreign-owned companies, FOCI is almost certainly the word that sent you here — and it is pointed somewhere other than where you think. The Cybersecurity Maturity Model Certification Program Rule at 32 CFR Part 170 contains no ownership test, no parentage test, and no citizenship test for the company being assessed. It does contain a Foreign Ownership, Control or Influence (FOCI) screen. That screen applies to the C3PAO that would assess you and, in parallel, to the Accreditation Body — not to the contractor being assessed.

That is the answer. Here are the conditions that change what you do next.

Your CMMC level comes from the contract clause and the information you handle — Level 1 for Federal Contract Information (FCI), Level 2 against NIST SP 800-171 Revision 2 for Controlled Unclassified Information (CUI), and Level 3 when DoD designates it in the contract, adding 24 selected NIST SP 800-172 requirements after a Final Level 2 (C3PAO) prerequisite. Foreign ownership does not move you up that ladder.

What foreign ownership genuinely changes is four things, and they are separable: which organization, assessment scope, and CMMC Unique Identifier (UID) the status covers; how much of your foreign parent's IT gets pulled into that scope; whether specific foreign nationals may access specific CUI; and what you may have to disclose to the Defense Counterintelligence and Security Agency (DCSA) if a rule proposed on May 7, 2026 is finalized.

Most of the confusion on this topic comes from one mistake: treating CMMC, traditional FOCI, export control, and the new proposed disclosure rule as one escalating process. They are separate systems with separate triggers under separate authorities. It is completely normal to sit inside one and outside another.

We read the actual rule text for this page — 32 CFR § 170.9 and § 170.8 in the CMMC rule, 32 CFR § 117.11 in the National Industrial Security Program Operating Manual (NISPOM), and the current July 2026 revision of Standard Form 328 itself, including the authority statement most people never scroll down to. Two findings below are our own cross-source synthesis. Both are checkable in about two clicks.

Who this page is for: U.S. subsidiaries of foreign parents, foreign-owned DIB suppliers, non-U.S. primes and subcontractors performing on DoD work, and any U.S. contractor whose systems are administered from outside the United States.

Who should start somewhere else. If your only foreign exposure is a passive investor below the disclosure thresholds we cover in the SF-328 section, you have an ordinary CMMC problem — start with CMMC levels and stop reading here. If your real question is about facility-clearance eligibility and classified work, start with your Facility Security Officer and industrial-security counsel. If you already know your level and just need the assessment-type comparison, go to Level 2 self-assessment vs. C3PAO. We would rather lose the pageview than waste your afternoon.

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining material regulatory claims with primary-source citation and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they commit to an expensive compliance path.


Status check: two 2026 developments people are blending together

August 2026 update. CMMC Phase I began on November 10, 2025 and was originally scheduled to run through November 9, 2026. On July 13, 2026, the Department suspended the transition to Phase II and the later implementation milestones. No replacement Phase II date has been announced. During the review period, program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self); the implementing memorandum directs that they may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).

The suspension did not erase the underlying contract duties. DFARS 252.204-7012 safeguarding and incident-reporting obligations remain in effect. The SPRS assessment-score duties in DFARS 252.204-7019 and -7020, and the CMMC result and annual-affirmation duties in DFARS 252.204-7021, remain where those clauses apply. NIST SP 800-171 Revision 2 remains the Level 2 assessment baseline until DoD changes Part 170 through rulemaking.

Separately — and this is the one that trips up foreign-owned readers — a proposed DFARS rule published May 7, 2026 would extend FOCI and beneficial-ownership review to certain DoD contracts and subcontracts valued in excess of $5 million. Commercial products and services would generally be excluded unless a designated senior DoD official made the proposal's national-security-risk determination. It is proposed. It is not final. Every sentence we write about it below is conditional, and it should be conditional in your board deck too.

Two different rules, two different directions, two different clocks. Keep them apart and this topic gets much easier.


The 30-second version

Question — Bottom line
QuestionBottom line
Can a foreign-owned company obtain the CMMC status its contract requires?Yes. Ownership and headquarters are not the CMMC test.
Does foreign ownership raise your CMMC level?No. The contract clause and the information you handle set the level.
Where does FOCI appear in the CMMC rule?32 CFR § 170.9(b)(5) for C3PAOs and § 170.8(b)(5) for the Accreditation Body — not for the contractor being assessed.
Does CMMC resolve FOCI?No. They are separate determinations under separate authorities.
Does your existing FOCI mitigation agreement make you CMMC compliant?No. But artifacts such as an ECP, AOP, or TCP can do real work for you.
Can foreign nationals access CUI?Sometimes. The CUI category, limited dissemination control, export law, and contract terms decide — not NIST SP 800-171.
Can your foreign parent's IT team administer your systems?Possibly — but privileged capability can pull identities, services, systems, and security tooling into your assessment scope.
Is the $5 million figure a CMMC threshold?No. It belongs to the separate proposed FOCI rule.
What should you do first?Document the contract, the data, the ownership, and the access paths — before you hire an assessor.

The right provider isn't the same for every contractor

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

We use the full names on first mention throughout, because these acronyms get used loosely and the differences matter: C3PAO (CMMC Third-Party Assessment Organization — the entity authorized to perform Level 2 certification assessments), RPO/RP (Registered Practitioner Organization / Registered Practitioner — non-certified readiness and advisory), MSSP (Managed Security Service Provider), GRC platform (governance, risk, and compliance software for evidence and workflow), and CUI enclave (a purpose-built, bounded environment for handling Controlled Unclassified Information).


CMMC for foreign-owned companies: does the rule apply?

Yes. CMMC applies when a covered DoD solicitation or contract requires the contractor to process, store, or transmit Federal Contract Information or Controlled Unclassified Information on unclassified contractor information systems above the micro-purchase threshold, with an exception for contracts exclusively for commercially available off-the-shelf items. Ownership, parentage, and headquarters location are not part of that test.

That test lives at 32 CFR § 170.3(c). Read it once and you will notice what is missing: there is no ownership percentage, no nationality question, no parent-company inquiry. The rule regulates data and systems.

Three variations, because "foreign-owned" covers three very different companies:

You are a U.S. subsidiary of a foreign parent

Your U.S. entity can define its own CMMC assessment scope and obtain the required status for that scope. The parent's ownership stake does not determine your level. What the parent can affect is your scope — through shared services, administrative access, and governance rights. We take that apart in detail below.

You are headquartered outside the United States

You can be subject to CMMC as a prime or a subcontractor. There is no national-equivalency exemption. Your home country's cybersecurity certification, however rigorous, does not substitute.

The Department's July 2026 CMMC FAQ answers the international question directly: when a solicitation identifies a CMMC requirement, it applies to companies performing under the resulting contract whether they are domestic or international. A home-country certification does not create blanket CMMC reciprocity.

An international agreement or contract-specific authorization can affect access and performance on a particular contract, but Part 170 creates no blanket CMMC reciprocity. Never assume an exception applies; ask your contracting officer to identify the exact agreement and contract language if someone tells you it does.

You are a foreign subcontractor

Flow-down follows the information, not the passport. If you will handle FCI or CUI in performance, the requirement can flow to you. DFARS 252.204-7021 requires primes to flow down the substance of the CMMC clause, and DFARS 252.204-7012 flows down for subcontracts involving covered defense information or operationally critical support. A foreign address does not create a lower standard or a softer version. See CMMC requirements for subcontractors for the flow-down mechanics.

What a CMMC status actually proves — and what it does not

This is where a lot of expensive misunderstanding starts, so we will be blunt about the boundaries.

A CMMC status supports one conclusion: that the named assessment scope achieved the recorded CMMC status under Part 170. A Final status and a Conditional status do not mean the same thing; a Conditional status carries permitted Plan of Action and Milestones items that must be closed on the rule's schedule. It does not grant a facility clearance. It does not resolve FOCI. It does not constitute an export authorization. It does not entitle any particular foreign person to access any particular item of CUI. And it does not override a more restrictive marking, contract term, or prime requirement.


Does foreign ownership change your CMMC level?

No. CMMC levels are set by the contract clause and the information handled: Level 1 for Federal Contract Information, Level 2 for Controlled Unclassified Information, and Level 3 when DoD specifically designates it in the contract and requires the 24 selected NIST SP 800-172 requirements after a Final Level 2 (C3PAO) prerequisite. Nothing in 32 CFR Part 170 escalates a required level because of who owns the company.

Level 2 currently maps to NIST SP 800-171 Revision 2 — 110 security requirements across 14 families — under 32 CFR § 170.14(c)(3). NIST has superseded Revision 2 as a publication, but DoD's July 2026 FAQ confirms that Revision 2 remains the CMMC assessment baseline until Part 170 is changed through rulemaking. That mapping holds regardless of your cap table. If you want the level-by-level breakdown, we keep it at CMMC levels rather than repeating it here.

What foreign ownership does change is scope, and scope is what actually drives cost. A U.S. subsidiary running entirely on its own infrastructure and a U.S. subsidiary sitting inside its parent's global Microsoft tenant face the same 110 requirements and radically different bills. That is a boundary problem, not a level problem, and confusing the two is how companies end up buying the wrong engagement. See CMMC Level 2 cost for the cost drivers once the boundary is known.


Where does FOCI actually appear in the CMMC rule?

In two parallel places. Section 170.9(b)(5) requires a CMMC Third-Party Assessment Organization to submit Standard Form 328 on request from DCSA, undergo a National Security Review regarding the protection of controlled unclassified information, and obtain a non-disqualifying eligibility determination from the CMMC Program Management Office. Section 170.8(b)(5) imposes the parallel screen on the Accreditation Body. Neither provision applies to the contractor being assessed.

We read § 170.9 in full at the eCFR on August 18, 2026 (Title 32 current as of August 14, 2026). Here is what a C3PAO must do, in the rule's own structure:

  • § 170.9(b)(5)(i) — complete and submit SF-328, Certificate Pertaining to Foreign Interests, upon request from DCSA, and undergo a National Security Review "with regards to the protection of controlled unclassified information," based on the factors identified in 32 CFR § 117.11(b) using the procedures at § 117.11(c).
  • § 170.9(b)(5)(ii) — receive a non-disqualifying eligibility determination from the CMMC PMO resulting from the FOCI risk assessment in order to proceed to a DCMA DIBCAC (Defense Contract Management Agency Defense Industrial Base Cybersecurity Assessment Center) CMMC Level 2 assessment.
  • § 170.9(b)(5)(iii) — report any change to the SF-328 by resubmitting to DCSA within 15 business days of the change becoming effective. A disqualifying determination based on that change, the rule says plainly, "will result in the C3PAO losing its authorization or accreditation."

The Accreditation Body carries the same burden under § 170.8: complete the SF-328, submit it directly to DCSA, undergo the same National Security Review regarding CUI protection, and receive a non-disqualifying eligibility determination from the CMMC PMO to be recognized by the Department — with the same 15-business-day clock.

Three things worth noticing from reading these provisions together.

First, the CMMC rule borrowed a classified-information tool and re-pointed it at unclassified information. The FOCI factors and procedures in § 117.11 exist to protect classified information. Section 170.9(b)(5)(i) imports them and redirects the review toward protecting controlled unclassified information. That is a deliberate adaptation inside the CMMC ecosystem.

Second, search Part 170 for an ownership test on the assessed contractor and you will not find one. We looked. Applicability turns on data and systems. The FOCI machinery turns on the assessor and the accreditor. That is the whole architecture.

Third — and this is our editorial read, not the rule's stated rationale — the asymmetry is coherent. A C3PAO may see inside multiple contractors' CUI environments and authors assessment records that flow through eMASS to SPRS. An assessed contractor's CMMC status is confined to its own assessment scope. Putting the ownership screen on the party with aggregated visibility across the industrial base is a defensible design choice rather than an oversight.

What this means for you, in one sentence you can forward to your parent company's board: under the CMMC Program Rule as written, being foreign-owned does not raise your CMMC level, does not add a security requirement, does not make you ineligible for certification, and does not create a foreign-ownership-based assessor restriction for the contractor. Part 170 screens C3PAOs and the Accreditation Body on their own FOCI; your ownership raises questions in other regimes that CMMC does not answer.

Not sure which of these regimes is actually blocking you?

The common blockage here is a mapping problem, not a single compliance problem. The Defense Compliance Report's Find My CMMC Path tool maps your required level, FCI or CUI handling, assessment type, cloud and IT environment, and contract timeline to the provider category that fits — not to a ranked vendor list. It takes a few minutes and asks for nothing sensitive.

Map my situation to a provider category →

Do not submit CUI, classified information, drawings, export-controlled technical data, contract attachments, SSPs, network diagrams, or ownership documents.


What is FOCI, and how do we know if we are under it?

Under 32 CFR § 117.11(a)(1), a Cognizant Security Agency considers a U.S. entity to be under FOCI when a foreign interest has the power to direct or decide issues affecting the entity's management or operations in a manner that could result in unauthorized access to classified information or adversely affect performance of a classified contract. The screening instrument is Standard Form 328, and its questions carry specific thresholds — including 5 percent foreign ownership and, under Question 7, 5 percent from a single foreign source or 15 percent in aggregate across revenue, net income, tuition, gifts, and endowments.

Before the mechanics, read the rule's opening line, because every foreign-owned executive should see it:

"Foreign investment can play an important role in maintaining the vitality of the U.S. industrial base." — 32 CFR § 117.11(a)

The regulation then states the Government's intent to allow that investment when it is consistent with U.S. national-security interests. You are not presumed to be a problem. You are presumed to be reviewable.

The classified-access hinge

Read § 117.11(a)(1) closely and you will see what the whole section is about: unauthorized access to classified information, and performance of classified contracts. Traditional FOCI is a classified-access construct administered by DCSA as a Cognizant Security Agency. Section 117.11(a)(3) makes the consequence explicit — an entity in process for an entity eligibility determination that is then found to be under FOCI is ineligible for access to classified information until effective measures are in place.

If your company is not seeking or maintaining entity eligibility for access to classified information, § 117.11 is generally not the process assessing you today. The proposed rule we cover further down is what would extend a related disclosure and review process to certain unclassified awards if finalized. This distinction is the single most useful thing on this page for a foreign-owned company with unclassified CUI work and no facility clearance, and most explanations blur it.

The nine SF-328 questions and the thresholds that matter

We pulled the current July 2026 revision of the form and its instructions from GSA (OMB Control Number 0704-0579; approval expires May 31, 2027). Definitions follow 32 CFR § 117.3, and the form adds one for the avoidance of doubt: an entity over which control is exercised or exercisable by a foreign person is itself a foreign person, referencing 31 CFR § 800.224.

# — What the form asks — Threshold
#What the form asksThreshold
1Does any foreign person directly or indirectly own, beneficially own, or subscribe to shares, participation interests, units, or total capital commitment?5% or more
2Does your organization own any foreign interest, directly or through subsidiaries or affiliates?10% or more
3Do any foreign persons serve on your governing body or hold a management position?Any
4Does any foreign person have binding authority or the power — whether or not exercised — to control your governing body, management positions, decisions, or activities?Any
5Do you have any contracts, agreements, understandings, grants, side letters, or arrangements with a foreign person?Any
6Any indebtedness, liabilities, or obligations to a foreign person? Answer yes if the debt is with a U.S. entity that is itself foreign-owned or controlled.Any
7Last fiscal year, did you derive revenue, net income, tuition, gifts, or endowments from foreign persons?5% from any single foreign person, or 15% in aggregate
8Do any of your management hold positions with, or serve as consultants or representatives for, any foreign person?Any
9Any other facts indicating a foreign person could control or influence your operations in a manner allowing unauthorized access to U.S. Government information or adversely affecting contract performance?Any

Practical notes from the form itself: a corporate family may file a consolidated response rather than separate submissions, per § 117.11(c). The completed form is itself CUI — marked with the PROPIN category and the FEDCON limited dissemination control. And 18 U.S.C. § 1001 false-statement exposure is stated on its face. This is not a questionnaire to delegate to someone who will guess.

The eight factors DCSA actually weighs

If your answer to "how will they judge us?" is currently a shrug, § 117.11(b) lists the factors, considered in the aggregate: any record of espionage against U.S. economic or government targets; any record of enforcement actions for unauthorized technology transfer; the record of compliance with U.S. laws, regulations, and contracts; the type and sensitivity of the information at issue; the source, nature, and extent of the FOCI — including whether the foreign interest holds a majority or minority position, taking into account immediate, intermediate, and ultimate parents; the nature of relevant bilateral and multilateral security agreements; direct or indirect ownership or control by a foreign government; and any other factor demonstrating a capability of foreign interests to control or influence operations or management.

Note what is not on that list: a single disqualifying ownership percentage. Governance rights, debt covenants, and contractual power can matter as much as equity.

One more original finding, and it is the bridge to your CMMC work

Here is the part of the current SF-328 that belongs on a cybersecurity page.

The form's authority statement lists five authorities. Item 5 names the CMMC program directly and states that eligibility to participate in the DoD CMMC program cannot be determined if the form is not completed accurately. It cites DFARS 252.204-7012 — the safeguarding clause — rather than the CMMC clause at 252.204-7021. Read together with § 170.9(b)(5), the CMMC-program filers the rule expressly identifies are ecosystem entities, so do not read this as a universal filing duty for every contractor. But the CMMC program is named in the form's own authority block, and the CMMC rule separately directs C3PAOs and the Accreditation Body into that form.

Then look at Question 5. Its supporting-documentation instructions require identification of foreign persons providing services including information technology, recruiting, human resources, accounting, finance, legal, manufacturing, business development, technological know-how, or any other service that substantially aids the organization's operations. The instructions also ask about foreign-derived products and services used in performing U.S. Government contracts and about export-controlled technology or information.

In other words: the FOCI form asks you to identify foreign persons providing IT and other listed operational services. CMMC scoping asks you to identify External Service Providers whose assets process, store, or transmit your CUI or Security Protection Data. These are frequently overlapping lists maintained for two different compliance processes.

Both records are readable by people who compare documents for a living. If your System Security Plan says your parent's help desk has no access while your SF-328 discloses the parent as your IT provider, you have manufactured a documentary conflict. Consistency across records is cheap to maintain and expensive to repair.


The Five Gates: which one is actually blocking you?

Foreign-owned contractors get stuck because they are trying to answer one question when five separate ones are in play: what the contract requires, whether classified work and traditional FOCI are involved, who may access the specific information, how a non-U.S. entity registers and gets assessed, and whether a proposed disclosure rule would apply. A "yes" at one gate does not answer the other four.

This is our framework, built from the sources cited throughout this page. It is a decision aid, not a government score and not a legal determination.

Gate — The question it answers — Controlling authority — What it does not answer
GateThe question it answersControlling authorityWhat it does not answer
1. Contract and CMMCDoes the contract require a CMMC status — at what level, what assessment type, over what scope?32 CFR Part 170; DFARS 252.204-7012, -7019, -7020, -7021, -7025; the solicitation itselfWhether your ownership presents a national-security concern
2. Classified work and traditional FOCICan a cleared U.S. entity obtain or keep classified access given its ownership and governance?32 CFR § 117.11; DCSAWhether your 110 NIST SP 800-171 Rev. 2 requirements are implemented
3. Foreign-person accessMay this specific person, parent, or provider access this specific information?CUI category and limited dissemination controls; ITAR (22 CFR § 120.50); EAR (15 CFR § 734.13); contract termsWhether the company as a whole holds a CMMC status
4. International processHow does a non-U.S. entity get its identifiers, reach the government systems, and complete an assessment?CMMC Final Rule; SAM; CAGE/NCAGE; PIEE; SPRSWhether an international agreement creates an exception
5. Proposed Section 847 disclosureWould the proposed pre-award beneficial-ownership and FOCI process reach a contract or subcontract valued in excess of $5 million if finalized?Proposed DFARS rule published May 7, 2026; DCSA implementation materialsYour current CMMC level or current clearance eligibility

Find yourself in this table

Your situation — CMMC path today — Traditional FOCI in play? — The foreign-access question — First evidence to collect — Who should help first
Your situationCMMC path todayTraditional FOCI in play?The foreign-access questionFirst evidence to collectWho should help first
Non-U.S. company handling FCI onlyLevel 1 self-assessment if the contract requires itNot the ordinary § 117.11 path absent classified accessContract terms and any dissemination restrictionSolicitation, FCI data flow, NCAGE, SAM statusRPO/readiness adviser; contracts counsel if applicability is unclear
Non-U.S. company handling CUILevel 2 path; verify the written requirement and current phaseSeparate unless classified access is involvedCUI category, markings, export statusClause list, CUI categories, data-flow map, foreign-user listContracts and export counsel, then readiness
U.S. subsidiary of a foreign parent, CUI, no facility clearanceCMMC applies on ordinary termsNot the ordinary § 117.11 process absent classified-access eligibility; watch Gate 5Parent administration, shared tenant, foreign staffOwnership chart, parent service agreements, privilege mapCounsel on governance, then RPO; enclave design after access is mapped
Foreign-owned U.S. subsidiary pursuing an FCL or classified workCMMC still governs the unclassified FCI/CUI sideYes — you are inside itTechnology Control Plan scope, foreign visitsSF-328 package, governance documents, DD Form 254FSO and industrial-security counsel before CMMC implementation
Already under an SSA, SCA, Proxy, or Voting TrustThe agreement is not a CMMC substituteYes — it governs your classified-side riskAlign the TCP and ECP with your CUI access designMitigation agreement, TCP, ECP, access listsFSO plus readiness team, working from existing documents
U.S. contractor with foreign global administratorsAchievable, but identities, services, systems, and security tooling may enter scopeAdministrator nationality alone is not a FOCI determinationPrivileged access, keys, logging, help deskGlobal-role export, tenant architecture, support contractsArchitecture/MSSP plus export counsel
Offshore SOC, SIEM, backup, or help deskThe service may be in scope as an External Service Provider or security protection assetUsually not ownership FOCI on its ownSecurity protection data, tickets, credentials, restore rightsData types sent, admin permissions, service description and CRMMSSP or enclave architect, plus counsel on access restrictions
Foreign subcontractor receiving FCI or CUIFlow-down follows the informationSeparate international arrangements govern classified workPrime-imposed limits and information markingsPrime flow-down letter, subcontract, data pathWritten prime clarification, then readiness adviser
Company applying to become a C3PAOA separate ecosystem authorization pathYes — § 170.9(b)(5) applies directlyAssessment confidentiality and personnel requirementsSF-328, ownership documents, staffing recordsThe Cyber AB authorization process and DCSA review

The scenario rows above are our editorial synthesis of the verified authorities cited on this page. Your contract governs. Confirm CMMC scope with a CMMC Registered Practitioner (RP) or Registered Practitioner Organization (RPO); take legal, contractual, export-control, and FOCI determinations to qualified counsel.


If we already have FOCI mitigation, does any of it count for CMMC?

No FOCI mitigation instrument transfers CMMC status, and no provision makes a CMMC status reciprocal with DCSA. What can carry over is work product: if your mitigation package includes them, an Electronic Communications Plan is already a parent-network-separation document, an Affiliated Operations Plan is already a shared-services inventory, and a Technology Control Plan is already a nationality-based access-control policy.

We read § 117.11 subsections (d) through (i) line by line to build this. The left column is the regulation. The right column is our analysis, labeled as such.

FOCI construct (32 CFR § 117.11) — What the NISPOM actually requires — Transfers CMMC status? — What it is worth for CMMC evidence (our analysis)
FOCI construct (32 CFR § 117.11)What the NISPOM actually requiresTransfers CMMC status?What it is worth for CMMC evidence (our analysis)
Board Resolution — (d)(2)(i)Used where the foreign interest cannot elect a board member. The board identifies the foreign shareholder and shares, acknowledges industrial-security obligations, and certifies that the foreign owner neither needs nor will receive unauthorized access to classified information and can be effectively kept from it. Annual certification goes to the CSA.NoModest. It is a governance artifact about classified access — but its structure is a workable template for a parallel board attestation on CUI access, which nothing requires but which can support a coherent CUI-governance narrative.
Security Control Agreement (SCA) — (d)(2)(ii)Where the foreign interest does not effectively control the entity but is entitled to board representation. At least one cleared U.S. citizen must serve as an outside director. The rule states there are no access limitations under an SCA.NoLow direct value. Establishes that a U.S.-controlled governance layer exists. Context for an assessor, not evidence.
Special Security Agreement (SSA) — (d)(2)(iii)Used where the foreign interest effectively owns or controls the entity. It preserves a foreign-owner board voice while denying majority representation and unauthorized classified access. A National Interest Determination may be required for proscribed information.NoModerate. The insulation architecture an SSA forces resembles the separation CMMC scoping rewards — but it is scoped to classified access and must be rebuilt for CUI.
Voting Trust / Proxy Agreement — (d)(2)(iv)Voting rights vest in cleared U.S. citizens approved by the U.S. Government. The entity must be structured and financed so it can operate as a viable business independently of the foreign owners' interests.NoHighest indirect value. The required operating independence is the internal argument for a separately budgeted, separately administered U.S. CUI environment.
Limited entity eligibility determination — (e)For entities unable or unwilling to mitigate. Narrow: a single defined contract or circumstance, generally requiring an industrial security agreement with the relevant foreign government, and access limitations apply to all employees regardless of citizenship.NoNone for CMMC. We include the row because readers who hold one need to know it buys nothing here.
Technology Control Plan (TCP) — (h)(1)Required for entities cleared under a Voting Trust, Proxy Agreement, SSA, or SCA. It must use measures designed to prevent unauthorized access by non-U.S.-citizen employees and visitors and limit access to information covered by a U.S. Government disclosure authorization, such as an approved export license or technical-assistance agreement. Measures include distinctive badges, escorts, segregated work areas, and security indoctrination.NoYour most reusable artifact. A TCP already documents nationality-based access control and ties it to export authorizations. Re-scope it from classified to CUI and map it to specific 800-171 requirements, and you have a strong starting point for the nationality-based portion of your access-control narrative.
Electronic Communications Plan (ECP) — (h)(2)A CSA-approved plan establishing technical and logical separation between the contractor and the foreign interest or affiliates. It includes a network description and configuration diagram showing what is shared and what is protected from parent or affiliate access, and addresses firewalls, remote administration, monitoring, maintenance, and separate email servers.NoOne of the strongest pre-existing scoping documents a mitigated contractor may have. Read that requirement next to a CMMC network diagram and asset inventory. The ECP already answers what is shared with the parent.
Affiliated Operations Plan (AOP) — (h)(3)Used where the U.S. contractor and foreign interest provide services to each other. The CSA-approved plan controls affiliated activities whether administrative, operational, or commercial and whether performed directly or through third-party providers.NoMaps almost directly onto the CMMC External Service Provider analysis. Same underlying facts, different agency, different reason.
Facilities Location Plan — (h)(4)Used where the contractor is collocated with or near the parent or an affiliate. The rule generally does not permit a U.S. entity to occupy the same address or location as the foreign parent or affiliate.NoRelevant to physical protection requirements and to any shared-office CUI handling question.
Government Security Committee (GSC) — (g)Required under a Voting Trust, Proxy Agreement, SSA, or SCA. A permanent board committee. The Facility Security Officer is principal advisor and attends; the GSC chairman must concur in the appointment and replacement of the FSO.NoGovernance value. A standing board-level security body is the natural sponsor for CUI budget decisions and the right home for the CMMC affirming-official conversation.
Annual review and certification — (i)The CSA meets with the GSC at least annually. The chairman submits an annual implementation and compliance report covering intentional and inadvertent compliance or noncompliance, procedure changes, management and board changes, and ownership or structural changes.NoRhythm value. You already run an annual board-level security attestation. The CMMC annual affirmation can ride the same calendar.
Trustees, proxy holders, outside directors — (f)Must be resident U.S. citizens, independent of the foreign interest and the entity, without prior involvement, and eligible for classified access at the entity's level.NoExplains the shape of your U.S. governance layer. There is no CMMC equivalent — Part 170 imposes no citizenship requirement on your personnel.

The honest summary: there is no reciprocity in either direction. Your mitigation agreement does not produce a CMMC status. Your CMMC status does not produce a DCSA eligibility determination. But some of the hardest CMMC scoping work may already exist in your DCSA file under different names.

One thing we will tell you that works against our own interest

Here is the part a lead-routing publication is not supposed to say.

The three hardest problems on this page cannot be safely resolved by a CMMC provider category alone. Not by an RPO alone. Not by an MSSP alone. Not by a GRC platform alone. Not by a C3PAO alone.

Whether your parent may provide your IT is a corporate-governance and intercompany-agreement question. Whether a specific foreign national may open a specific drawing is an export-control question for qualified export-control counsel or your empowered official. Whether your ownership triggers a DCSA filing is a question for counsel who practices industrial security.

If you hire a managed service provider before those three answers exist, you can pay to build and secure an architecture that your legal structure then forces you to redesign. It is one of the most expensive mistakes available to a foreign-owned contractor right now, and we have no financial reason to warn you about it.

Now the pivot, because the sequencing is the whole point. Once those three answers exist, a provider category is exactly the right answer for everything downstream — an enclave design that can keep parent services out of scope when the boundary is real, the evidence work, the readiness. Order matters more than vendor. If you are in the "we need counsel first" position, start with who to hire first and use the four written questions further down this page before you spend a dollar.

Before you redesign anything, find out what Part 170 pulls into scope

Our 32-point CMMC Level 2 Readiness Checklist covers scope, the SSP and POA&M, SPRS, MSP/MSSP alignment, and pre-assessment evidence, with shared-services and external-provider questions surfaced. It is a fast way to see which parent-provided services become your problem. The PDF is free and delivered by email; do not submit contracts, CUI, or sensitive files.

Get the CMMC Readiness Checklist →


Can our foreign-national employees access CUI?

It depends on four things, none of which is decided by NIST SP 800-171 alone: whether the information has been identified as CUI, the CUI category and any limited dissemination control, export-control law, and contract-specific restrictions. NIST SP 800-171 Rev. 2 contains no citizenship requirement — it requires that system access be limited to authorized users. Whether a foreign person is an authorized user for a specific item is decided outside the control set, then enforced by the controls.

The order of operations matters, so work it in this sequence.

Step 1: Confirm the information has actually been identified as CUI, and find its category. An internal label applied by a recipient is not itself the designation. Start with the contract, the designating agency or prime, and the markings or written handling instructions.

Step 2: Read the limited dissemination control. These are published in the National Archives CUI Registry, and they are what actually govern foreign access:

Control — Marking — What it means for a foreign person
ControlMarkingWhat it means for a foreign person
No foreign disseminationNOFORNMay not be disseminated in any form to foreign governments, foreign nationals, non-U.S. citizens, or foreign or international organizations
Federal employees onlyFED ONLYExecutive-branch employees and members of the U.S. Armed Forces
Federal employees and contractors onlyFEDCONExecutive-branch employees, U.S. Armed Forces personnel, and contractors when dissemination furthers a contractual purpose
No dissemination to contractorsNOCONBars dissemination to federal contractors; state, local, and tribal employees may still receive it
Dissemination list controlledDL ONLYOnly the named individuals or entities; the list must accompany the document
Authorized for release toREL TO [USA, LIST]Release authorized only to the countries or organizations named
Display onlyDISPLAY ONLY [USA, LIST]May be shown to the named foreign recipients, but no physical or electronic copy may be left with them for retention

Two rules people get wrong. Only the designating agency may apply these controls — under 32 CFR § 2002.16, a recipient who wants to add one must request permission from the designating agency. And using limited dissemination controls to unnecessarily restrict access is contrary to the CUI Program's own goals. Over-marking is not the safe play it appears to be.

Step 3: Run the export-control analysis, because it is separate and it is stricter. Under ITAR at 22 CFR § 120.50(a)(2), releasing or otherwise transferring technical data to a foreign person inside the United States is a "deemed export." Section 120.50(b) deems that release an export to every country in which the person has held or holds citizenship or permanent residency. The EAR parallel sits at 15 CFR § 734.13(a)(2) and (b) for technology and source code.

That is the provision that surprises people. Your foreign-national engineer sitting in Michigan, opening ITAR-controlled technical data, is an export event under the ITAR framework — not merely a network-security event. Any exception or authorization is fact-specific; the deemed-export rule is not a self-service determination. Take that one to export counsel.

Step 4: Distinguish two different events. Access by a foreign-national employee inside the United States and transmission to your parent abroad are different transactions with different analyses and frequently different answers. Companies that collapse them into one policy end up either over-restricting their own staff or under-controlling their parent relationship.

Step 5: Ask for the markings in writing. Nobody — not us, not your MSP, not your assessor — can answer the access question without knowing the CUI categories and any limited dissemination controls on your contract. Request them from your contracting officer or prime. The template is below.

Where NIST SP 800-171 does bite: access control (the 3.1 family), personnel security (3.9), and the System Security Plan narrative that has to explain your access model to an assessor coherently. Your controls do not decide who is authorized. Your controls have to enforce whatever decision the markings and export authorizations produce — and document it.

One claim to strike from your internal vocabulary: "CMMC requires all CUI to stay in the United States." That is not an accurate statement of the governing rules. If a location restriction applies to you, it comes from a specific contract term, a specific marking, a cloud requirement, or an export authority. Name the source or drop the claim.


Can our foreign parent or an offshore administrator run our systems?

CMMC imposes no categorical nationality ban on system administrators. But privileged access can pull identities, endpoints, parent services, and security tooling into your assessment scope, and it can independently trigger export-control or dissemination problems. The analysis follows actual technical capability, not org-chart titles.

Start with the definition, because it is narrower than most people assume. Under 32 CFR § 170.4, an External Service Provider (ESP) is external people, technology, or facilities used to provide or manage IT or cybersecurity services on the organization's behalf — and in the CMMC program, CUI or Security Protection Data (log data, configuration data) must be processed, stored, or transmitted on the ESP's assets for it to be an ESP at all.

Your parent is not exempt because it is your parent. If it meets that definition, § 170.19(c)(2) governs. The use of the ESP, its relationship to you, and the services provided must be documented in your System Security Plan and described in the ESP's service description and customer responsibility matrix (CRM). An ESP may voluntarily obtain its own CMMC status, but it is not required to do so; the services it provides are still assessed within your scope as the rule specifies, and any voluntary minimum assessment type follows your contract requirement. We keep the full decision tree at CMMC external service provider assessment rather than repeating it here.

What changes the answer is what the offshore team can actually do. Audit for capability, not intent.

Parent-controlled Active Directory and Group Policy

Can the parent push software, change endpoint configuration, create accounts, reset passwords, disable monitoring, alter firewall or endpoint rules, change certificate or encryption settings, grant local administrative rights, or redirect traffic? Every "yes" is a scope conversation and possibly an access conversation.

Global administrators in a shared cloud tenant

Document tenant ownership, Global Administrator role assignments, privileged identity management, break-glass accounts, eDiscovery and content-search rights, encryption-key control, conditional-access policy ownership, log access, support escalation paths, cross-tenant synchronization, and backup and restore privileges. A parent administrator who has never opened a CUI file but holds eDiscovery rights over the tenant has effective access. Assessors know to look.

Offshore SOC or SIEM

Ask whether logs contain Security Protection Data, whether tickets carry screenshots, filenames, or user data, whether the provider can act remotely on endpoints, whether it can alter or suppress evidence, and where credentials and session recordings live. Under the CMMC scoping model, a provider whose assets process Security Protection Data without CUI is in your assessment scope as a security protection asset and is assessed against the requirements relevant to the capabilities it provides.

Offshore help desk

Password resets, remote desktop, user impersonation, ticket attachments, device enrollment, local administrator elevation, identity proofing. Help desks are where theoretical separation dies.

Backup and disaster recovery

Backup location, restore privileges, key custody, vendor support access, replication targets, and metadata. The question that matters: could CUI be restored into an uncontrolled environment by someone outside your boundary?

Three architectures, honestly compared

Architecture — Best fit — Main advantage — Main risk — What you must be able to prove
ArchitectureBest fitMain advantageMain riskWhat you must be able to prove
Shared parent environmentParent services are permitted and can meet the applicable requirementsLeast duplication of cost and effortLarge scope; foreign privileged access is complex to boundParent-side controls, responsibility split via CRM, access authorization, evidence availability on demand
Segmented U.S. subsidiary environmentThe U.S. entity needs real operational independenceA defensible boundaryParent integrations quietly reopen the boundarySeparation of identity, endpoints, network, support, logging, and keys
Dedicated CUI enclaveA limited set of users and workflows handle CUIPotentially much smaller scopeEndpoints, integrations, and indirect admin access can break isolationThe data path, the user path, the admin path, the security-protection path

Our view: enclaves are the most oversold answer in this market. An enclave that a parent-company global administrator can reach is not a clean boundary — it is a folder with ambitions. If you are pricing one, CMMC enclave cost and GCC High for CMMC cover the economics and the platform questions.

One consistency check before you build: if your FOCI mitigation package includes an Electronic Communications Plan, it already describes which networks are shared with the parent. Your System Security Plan is about to describe the same thing. Those two documents must not disagree.


How does a non-U.S. company actually register and get assessed?

International contractors use the same general CMMC process as domestic contractors, and the practical obstacle is usually identifiers and system access rather than security requirements. A non-U.S. entity typically needs an NCAGE code, an active System for Award Management registration with a Unique Entity ID, Procurement Integrated Enterprise Environment access, working Supplier Performance Risk System roles, and — once a status exists — a CMMC Unique Identifier (UID) that accurately represents the assessed scope used for contract performance.

This is the operational layer the rule text does not walk you through, and it is where non-U.S. companies can lose weeks.

Step 1 — Decide which legal entity is the contracting party. The U.S. subsidiary or the foreign parent? Which one will process the FCI or CUI? Which assessed scope will perform the work? Getting this wrong means re-doing the paperwork.

Step 2 — Get the right CAGE or NCAGE association. U.S.-based entities generally use a Commercial and Government Entity (CAGE) code. Non-U.S.-based entities generally use a NATO Commercial and Government Entity (NCAGE) code. Do not assume every office or facility needs its own code: the Department's July 2026 FAQ says an existing CAGE code within the company hierarchy may be used. CAGE and NCAGE codes control authorized SPRS access, annual affirmations, and program metrics; the CMMC UID is what represents the assessed information-system scope.

Step 3 — Register in SAM and align the Unique Entity ID. Legal name and address must match your corporate records. Resolve mismatches before a bid deadline, not during one.

Step 4 — Get Procurement Integrated Enterprise Environment (PIEE) access. PIEE is the gateway to DoD applications including SPRS. Every Vendor Group needs at least one Contractor Account Administrator (CAM). Document a backup and succession path before the only CAM leaves.

Step 5 — Confirm SPRS access, the CAGE or NCAGE association, and the CMMC UID. Verify the correct codes and scope, confirm SPRS Cyber Vendor User access for contractor-entered self-assessment information, and identify the Affirming Official responsible for the annual affirmation when one is required. For a certification assessment, confirm that the C3PAO is using the correct CAGE or NCAGE hierarchy for the assessment scope; after the result posts, verify that the resulting CMMC UID represents that scope. Offerors must identify every CMMC UID in the proposal that will process, store, or transmit FCI or CUI during performance.

Step 6 — Plan the logistics your U.S. competitors never think about. Two specifics worth knowing:

  • English-language assessment records. Under 32 CFR § 170.9(b)(7), a C3PAO must provide its documentation and records in English. The rule does not turn that sentence into a universal contractor-record language mandate, so confirm with your prospective assessor what evidence translation it will require and budget that work before scheduling.
  • Incident-reporting credentials. DFARS 252.204-7012(c) requires rapid reporting — within 72 hours of discovery — to DoD at dibnet.dod.mil, and § 252.204-7012(c)(3) requires the contractor or subcontractor to have or acquire a DoD-approved medium assurance certificate to do it. Provisioning that certificate takes time and identity verification. A non-U.S. entity should start that process well before it has an incident, not during one.

Time zones, travel, and on-site access also have to be negotiated with your assessor. None of this is a security requirement. All of it is a schedule risk.


Can a foreign-owned company be a C3PAO? Can a foreign C3PAO assess us?

Two different questions with two different answers. A foreign-owned company may apply to become a C3PAO, but the C3PAO must pass the FOCI screen at 32 CFR § 170.9(b)(5) and obtain a non-disqualifying eligibility determination from the CMMC Program Management Office. A disqualifying FOCI risk determination prevents it from proceeding, but foreign ownership is not an automatic bar. An authorized C3PAO may assess an organization outside its home country; Part 170 creates no same-country restriction. The Department's July 2026 FAQ says individuals and organizations may apply for CMMC ecosystem roles regardless of nationality or country of origin if they meet every requirement in Part 170.

For you as a buyer, the practical consequence is a due-diligence step, not a barrier: verify your prospective C3PAO's current authorization status before you sign anything. A firm's authorization can change. We keep the verification path at find an authorized C3PAO and the caveats about circulating ecosystem counts at the Cyber AB Marketplace guide.

The same official FAQ says CMMC requirements apply to domestic and international companies when the solicitation identifies them. Nothing in Part 170 creates a home-country rule that limits an authorized C3PAO to assessing only organizations in the same country. Authorization status and the requirements of the particular assessment — not marketing geography — are the checks that matter.

On the "assessors must be U.S. citizens" myth. Part 170 requires C3PAO personnel participating in Level 2 certification assessments to initiate a Tier 3 background investigation through the SF-86 process. For personnel who are not eligible for a Tier 3 investigation, including because they are not U.S. citizens, DoD must determine the equivalent of a favorably adjudicated Tier 3 investigation for CMMC use. Part 170 does not impose a blanket citizenship requirement on your workforce. If a citizenship restriction applies to your work, it comes from a marking, an export authority, or a contract term — Gate 3, not Gate 1.

One independence rule you cannot design around. Under § 170.8(b)(17)(ii)(G), the Accreditation Body's required Code of Professional Conduct must prohibit a CMMC ecosystem member from participating in a Level 2 certification assessment for an organization it served as a consultant to prepare for a CMMC assessment within the preceding three years. Keep readiness and formal assessment in separate contracts with separate firms. If you are weighing a practice assessment, CMMC mock assessment covers where that line sits.


Is the May 2026 DFARS FOCI rule the same as CMMC?

No. On May 7, 2026, DoD published a proposed DFARS rule that would extend FOCI and beneficial-ownership disclosure and review to existing and prospective DoD contractors and subcontractors at any tier for contracts valued in excess of $5 million. It implements Section 847 of the FY2020 National Defense Authorization Act and Section 819 of the FY2021 NDAA. It is a separate authority from CMMC, and as of August 18, 2026 it is proposed — not final.

As proposed, covered offerors would submit SF-328, supporting documents, and beneficial-owner contact information through the National Industrial Security System (NISS). An eligible NISS status would become a condition DoD checks before award, modification, option exercise, or other extension. If DCSA identified mitigable risk, the offeror would agree at award to implement the directed risk-mitigation strategy within 90 days. During performance, any FOCI or beneficial-ownership change would require an updated SF-328 in NISS. If the contractor determines that a change may place it or a lower-tier entity under FOCI, it would have three business days to report the specified owner and mitigation information. After DCSA notifies the contractor that the condition presents a risk, the contractor would have 10 business days to initiate a plan, provide the requested information, and confirm compliance with the identified recommendations. The clause would flow to covered subcontracts and other covered instruments valued in excess of $5 million.

Commercial products and commercial services would generally be outside the proposed requirements unless a designated senior DoD official determined that the contract presents a national-security risk or potential compromise involving sensitive data, systems, or processes. The Federal Register proposal says that official had not yet been designated when the proposal published.

Current versus proposed, on one screen

Requirement — Current as of August 18, 2026?
RequirementCurrent as of August 18, 2026?
CMMC Phase I began November 10, 2025Yes
The originally scheduled November 10, 2026 Phase II transitionNo — suspended July 13, 2026; no replacement date announced
DFARS 252.204-7012 safeguarding obligationsYes, where the clause is in your contract
NIST SP 800-171 Rev. 2 as the Level 2 baselineYes, until DoD changes Part 170 through rulemaking
Traditional FOCI review for entity eligibility and classified accessYes, under 32 CFR § 117.11
C3PAO and Accreditation Body FOCI reviewYes, under 32 CFR §§ 170.9 and 170.8
Section 847 pre-award FOCI process for covered awards in excess of $5 millionNot final — proposed
A blanket U.S.-citizenship rule for all CUINo — not a CMMC rule
A blanket exemption for foreign contractorsNo — CMMC applies when the solicitation and contract require it

One number to stop repeating in internal meetings

$5 million is not a CMMC threshold. It belongs to the separate proposed FOCI and beneficial-ownership rule. CMMC applicability runs on its own terms — the solicitation, the clause, the information handled, the phase, and the micro-purchase threshold. Treating this single number as a CMMC threshold sends companies down the wrong compliance path, and it costs real money.

The only genuine urgency here is your own calendar. If that rule finalizes materially as proposed, NISS eligibility would become a precondition to award, modification, option exercise, or other extension for covered actions. That means your real deadlines would be your next bid date, next modification, next option exercise, or other covered extension — not a countdown clock on a website. We will not manufacture one, and neither should your vendors.

And the honest limitation: we cannot tell you what the final rule will require, because it does not exist yet. Anyone publishing a compliance date for it is guessing. Watch the Federal Register and DCSA's own implementation materials.


What to gather before you hire anyone

A useful first engagement requires facts about the contract, the information, the entity, the ownership, and the access paths — not a statement that the company is foreign-owned. Assembling these first reduces duplicated discovery, contradictory advice from different vendors, and premature architecture quotes.

This is the part you can do this week, for free, before anyone sends you a proposal.

Contract records: the solicitation and contract, the subcontract and any flow-down letter, the relevant FAR and DFARS clauses, the statement of work, the written CMMC status requirement, the contract value, commercial versus non-commercial treatment, and the bid, award, and option dates.

Information records: an FCI inventory, the CUI categories present, the actual markings including any limited dissemination controls, export-control classification, data owners, inbound and outbound paths, and any hardcopy workflow.

Ownership records: the legal-entity chart, ultimate parent, beneficial owners, capitalization table, board composition, veto and governance rights, debt and lender rights, management and parent service agreements.

Industrial-security records, if applicable: facility clearance status, DD Form 254, SF-328, changed-condition reports, the mitigation agreement, TCP, ECP, and your FSO's contact and responsibilities.

CMMC and system records: CAGE or NCAGE, Unique Entity ID, SAM status, PIEE and SPRS roles, the CMMC UID for each assessed scope, current SPRS score or CMMC status, System Security Plan, Plan of Action and Milestones, asset inventory, network and data-flow diagrams, External Service Provider inventory, and customer responsibility matrices.

Foreign-access records: role and employing entity for each person with access, direct and indirect privileges, remote-access paths, key custody, logging and monitoring access, support escalation, session recording, and the approval and revocation process.

Keep all of that inside your own approved systems. Our public forms do not request CUI, contract attachments, ownership documents, credentials, or network diagrams. Do not submit those materials through a public form or email them unless you have independently verified the recipient and the secure channel.

The four written questions that unlock everything else

Send these before you spend money. Each one changes the architecture, and each answer takes someone else's clock, not yours — which is why they should start today.

1. To your contracting officer or prime.

"For [contract/solicitation number], please identify the CUI categories anticipated in performance and any limited dissemination controls that apply, along with the required CMMC level and assessment type. We are scoping our environment and cannot determine authorized access without the applicable markings."

2. To your parent company's IT leadership.

"Please provide a written inventory of every service the parent provides to the U.S. entity, including administrative access levels, the location of each service, and which personnel hold privileged roles. We are documenting our assessment boundary and must be able to show which systems are shared."

3. To your general counsel or outside counsel.

"Please advise how 32 CFR § 117.11 applies to our ownership and governance; whether any current or anticipated contract requires access to classified information; and whether the DFARS rule proposed May 7, 2026 would cover any current or expected award if finalized as proposed."

4. To your export-control specialist or empowered official.

"Please identify which data under [contract] is controlled under ITAR or the EAR, and what authorization would be required before a specific foreign person could access it — including any release of ITAR-controlled technical data to a foreign person employed in the United States, which 22 CFR § 120.50(a)(2) treats as an export."


Who should help first — counsel, an FSO, an RPO, an MSSP, or a C3PAO?

The right first engagement depends on which gate is unresolved. Legal and contractual uncertainty belongs with qualified counsel; classified-work FOCI belongs with an FSO and industrial-security advisers; CMMC scope and readiness belong with an RPO or independent readiness consultant; environment build and operations belong with an MSP, MSSP, or enclave provider; and a C3PAO belongs at the formal assessment stage, separated from whoever did the remediation.

The question you cannot answer yet — Start with this category — What it should deliver — What it should never claim
The question you cannot answer yetStart with this categoryWhat it should deliverWhat it should never claim
Does the clause apply, and may foreign persons receive this data?Qualified federal-contracts and export-control counselWritten legal and contractual analysisA CMMC status
Does our ownership affect a facility clearance or an existing mitigation agreement?FSO, industrial-security adviser, qualified counselFOCI and FCL process guidance, government coordinationAuthority to approve mitigation
What is our CMMC scope, and where are the gaps?RPO or independent readiness consultantScope determination, gap analysis, remediation roadmapIndependence to assess its own work
How should the environment be built and operated?CMMC-focused MSP, MSSP, or CUI enclave providerArchitecture, implementation, operations, evidence generationA guaranteed certification outcome
How do we maintain evidence, the SSP, and the POA&M?GRC platform or documentation providerWorkflow and evidence managementThat software alone satisfies CMMC
Are we ready for a formal Level 2 assessment?A separately contracted authorized C3PAOAn independent assessmentRemediation of findings it would then assess
Is our required status unclear because of the suspension?Written clarification from the contracting officer or prime, plus counselA documented requirementA vendor's assumption

A note on why you will not find vendor names on this page. We route by category here, deliberately. On a page whose entire job is helping you figure out which of five regimes governs you, naming a vendor before you know that would undercut the only thing that makes this page useful. When a named-provider comparison genuinely helps a decision, we publish it with the provider's category, status verification source, compensation relationship, evaluation depth, and last-verified date visible on the page. This is not that page. Compare CMMC provider categories is where the category work lives.

Ready to translate all of this into a shortlist?

Tell us your required level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment — including whether a foreign parent provides any of your IT — and your contract timeline. The CMMC Path Framework maps that to the provider category that fits your situation. It routes to a category, not a ranked vendor list, and it is not a score or compliance advice.

Get matched with source-checked provider options →

If a foreign parent administers any part of your environment, say so in the scope field — it changes the match. Do not submit CUI, drawings, export-controlled data, contract attachments, SSPs, network diagrams, credentials, or ownership documents.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.


What we actually verified for this page

We separate three kinds of statements on this page: regulatory facts with a primary source, current-status facts with a verification date, and editorial judgments derived from both. Here is the audit trail.

Read directly at the source on August 18, 2026:

  • 32 CFR Part 170 — applicability at § 170.3; the Revision 2 and selected SP 800-172 baselines; the Accreditation Body and C3PAO FOCI provisions at §§ 170.8 and 170.9; C3PAO personnel investigations and English-language records; assessment results, affirmations, Level 3 prerequisites, scoping, and External Service Provider requirements.
  • The Department's July 13, 2026 CMMC reform memorandum, implementation memorandum, and July 2026 CMMC FAQ — the Phase II suspension, allowed assessment types during review, continued Revision 2 baseline, 24 Level 3 SP 800-172 requirements, international applicability, and eligibility for non-U.S. ecosystem participants.
  • DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025 — safeguarding, incident reporting, SPRS assessment-score duties, CMMC status and affirmation duties, and solicitation-level designation.
  • SAM.gov Entity Registration Checklist, PIEE Vendor Getting Started, and SPRS Access — NCAGE/SAM sequencing, PIEE Contractor Account Administrator requirements, and SPRS role access.
  • NIST SP 800-171 Revision 2 and NIST SP 800-172 — the 110 requirements across 14 families and the enhanced-requirement source used for Level 3.
  • 32 CFR § 117.11 — the traditional FOCI definition, eight factors, SF-328 procedures, mitigation instruments, Technology Control Plan, Electronic Communications Plan, Affiliated Operations Plan, Government Security Committee, and annual review.
  • Standard Form 328, current revision 07/2026 — the nine questions and thresholds, Question 5 service-provider documentation, CMMC authority statement, CUI/PROPIN/FEDCON markings, false-statement notice, and May 31, 2027 OMB expiration.
  • The May 7, 2026 proposed DFARS rule — Section 847 scope, the in-excess-of-$5-million threshold, NISS process, proposed deadlines, flow-down, commercial-treatment exception, and proposal status.
  • The National Archives CUI Registry limited-dissemination list, 32 CFR § 2002.16, 22 CFR § 120.50, and 15 CFR § 734.13 — limited dissemination controls and the ITAR/EAR release rules.
  • The Cyber AB's resource library and Marketplace — CMMC Assessment Process v2.0 (December 2024), Code of Professional Conduct v2.0 (December 2024), R2001 C3PAO Authorization Requirements v1.0 (January 2026), and the current public authorization directory. Part 170 controls if an ecosystem document conflicts with the rule.

Our editorial judgments, labeled as such: that CMMC, traditional FOCI, foreign-person access, international process, and the proposed Section 847 rule are five separate gates; that no FOCI mitigation instrument transfers CMMC status while the ECP, AOP, and TCP transfer real work product; that governance and export questions should be resolved before architecture spending; and that the correct engagement sequence runs counsel, then readiness, then environment, then assessment.

What we could not establish, and are not pretending to know: what the final Section 847 rule will require; whether DCSA would require any particular mitigation instrument in a given case, which is a DCSA determination rather than a published rule; and what implementation schedule will replace the suspended Phase II milestone.

This is educational research, not legal, contractual, export-control, industrial-security, or compliance advice. Confirm CMMC scope with a CMMC Registered Practitioner (RP) or Registered Practitioner Organization (RPO); take legal, contractual, export-control, and FOCI determinations to qualified counsel. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCSA, DCMA DIBCAC, NIST, or any U.S. government agency.

Our methodology, editorial standards, editorial review process, and corrections policy are public. If we got something wrong, tell us and we will fix it with a dated note.


Edge cases that need their own advice

A few situations cannot be resolved by any article, including this one. We would rather name them than pretend otherwise.

An existing international security agreement. Confirm its actual scope and language before relying on it. Country-level arrangements do not create CMMC reciprocity by default, and DoD's public position has been consistent on that point.

Joint ventures. Which entity is the awardee, which processes the information, which CMMC UID represents the assessed scope, and what access do the venture partners hold? Answer those four before scoping anything.

A merger or acquisition mid-readiness. Ownership and governance changes may require changed-condition reporting if you are cleared, and can change your boundary, your parent-service access, and potentially your assessment validity. Involve counsel and your FSO before closing, not after.

Multiple CAGE or NCAGE codes. Identify the assessed legal entity and map each code to the correct environment. One status does not automatically cover every affiliate or location.

Classified work and unclassified CUI in the same company. Two separate determinations, two separate document sets. Align them; do not merge them. Start with your FSO and industrial-security counsel for the classified side, then align the CMMC scope to that documented boundary.

Foreign-government ownership, or ownership traced to a country of concern. Escalate to qualified counsel immediately. We will not offer country-level generalizations, and no public form should be collecting your ownership documents.

A prime imposing conditions stricter than the rule. Get the requirement in writing and determine whether it is contractual, programmatic, or a questionnaire preference. Do not advise your team to ignore it because a website said the rule is narrower.


Frequently asked questions

Does CMMC apply to foreign-owned companies? Yes. Under 32 CFR § 170.3(c), CMMC applies where a covered solicitation or contract above the micro-purchase threshold requires the contractor to process, store, or transmit FCI or CUI on unclassified contractor information systems, with an exception for contracts exclusively for commercially available off-the-shelf items. Ownership and headquarters location are not part of that test.

Can a foreign-owned company get CMMC certified? Yes. Nothing in 32 CFR Part 170 makes a foreign-owned company ineligible for a CMMC status. The FOCI screen in the CMMC rule, at § 170.9(b)(5), applies to the C3PAO performing the assessment and, under § 170.8(b)(5), to the Accreditation Body — not to the organization being assessed.

Does foreign ownership raise your CMMC level? No. The level is set by the contract clause and the information handled: Level 1 for FCI; Level 2 against NIST SP 800-171 Rev. 2 for CUI; and Level 3, when specifically designated, adding 24 selected NIST SP 800-172 requirements after a Final Level 2 (C3PAO) prerequisite. Foreign ownership can increase your assessment scope, which affects cost, but it does not change the required level.

What does FOCI mean in the CMMC context? Foreign Ownership, Control or Influence. Under 32 CFR § 117.11(a)(1), a Cognizant Security Agency considers a U.S. entity to be under FOCI when a foreign interest has the power to direct or decide issues affecting the entity's management or operations in a manner that could result in unauthorized access to classified information or adversely affect classified contract performance. Within the CMMC rule specifically, FOCI appears as a screening requirement on assessment organizations.

Do we need a facility clearance to do CMMC? No. A facility clearance concerns eligibility for access to classified information under 32 CFR Part 117. CMMC concerns protection of FCI and CUI on unclassified contractor information systems under 32 CFR Part 170. They are separate determinations, and neither one produces the other.

Is a FOCI mitigation agreement the same as CMMC compliance? No. A Special Security Agreement, Security Control Agreement, Proxy Agreement, or Voting Trust addresses foreign ownership risk to classified information. CMMC assesses implementation of cybersecurity requirements over a defined FCI or CUI scope. A company can hold one and still owe the other entirely.

Can our Electronic Communications Plan be used for CMMC scoping? It does not transfer CMMC status, but it is genuinely useful. Under 32 CFR § 117.11(h)(2), an ECP must include a detailed network description and configuration diagram delineating which networks are shared with the foreign parent and which are protected from parent access — which is the same question a CMMC assessor asks about your boundary. Treat it as a starting document, not as evidence of compliance.

Can foreign nationals access CUI? Sometimes. NIST SP 800-171 Rev. 2 contains no citizenship requirement; it requires access be limited to authorized users. Whether a specific foreign person is authorized is determined by the CUI category, any limited dissemination control such as NOFORN, applicable export-control law, and the contract terms.

What does NOFORN mean for CUI? NOFORN is a limited dissemination control published in the National Archives CUI Registry meaning the information may not be disseminated in any form to foreign governments, foreign nationals, non-U.S. citizens, or foreign or international organizations. Under 32 CFR § 2002.16, only the designating agency may apply limited dissemination controls; a recipient seeking to add one must request permission.

Is a foreign national in the U.S. accessing controlled technical data an export? Under ITAR, yes — 22 CFR § 120.50(a)(2) defines releasing or transferring technical data to a foreign person in the United States as a deemed export, and § 120.50(b) treats it as an export to every country of that person's citizenship or permanent residency. The EAR parallel for technology and source code is at 15 CFR § 734.13. This analysis is separate from CMMC and belongs with export counsel.

Can our foreign parent's help desk administer our systems? Possibly, but it is a scoping decision with consequences. Under 32 CFR § 170.4, an External Service Provider is one whose assets process, store, or transmit your CUI or Security Protection Data. If the parent meets that definition, § 170.19(c)(2) applies and the relationship must be documented in your System Security Plan with a service description and customer responsibility matrix.

Can our CUI be stored in our parent's data center or a non-U.S. cloud region? There is no single blanket rule, and "CMMC requires all CUI to stay in the U.S." is not an accurate statement of the requirements. Any location restriction that applies to you comes from a specific contract term, a specific marking, a cloud service requirement, or an export authority — identify which one before designing around it.

Can a non-U.S. C3PAO assess a U.S. company? Yes, where the organization meets Part 170 and holds current authorization. DoD's July 2026 FAQ says organizations may apply for ecosystem roles regardless of nationality or country of origin if they meet the rule's requirements. Verify any prospective assessor's current status in the Cyber AB Marketplace before engaging it.

Can a foreign-owned company become a C3PAO? It must clear the FOCI screen at 32 CFR § 170.9(b)(5) — submitting SF-328 on DCSA request, undergoing a National Security Review regarding the protection of CUI, and receiving a non-disqualifying eligibility determination from the CMMC PMO before proceeding to its own DIBCAC Level 2 assessment. A disqualifying FOCI determination can prevent an assessment organization from proceeding, and changes to its SF-328 information must be reported within 15 business days.

Do CMMC assessors have to be U.S. citizens? No blanket citizenship rule appears in Part 170. C3PAO assessment personnel must initiate a Tier 3 background investigation through SF-86; for personnel who are not eligible, DoD determines the equivalent of a favorably adjudicated Tier 3 investigation for CMMC use. There is no blanket CMMC citizenship requirement applicable to your own workforce — restrictions on your personnel come from markings, export authorities, or contract terms.

Do we have to file an SF-328? Not as a general CMMC requirement for contractors. Under 32 CFR § 117.11(c) an entity completes SF-328 during the entity eligibility determination process or when significant changes occur, and under § 170.9(b)(5) C3PAOs file on DCSA request. The rule proposed May 7, 2026 would extend SF-328 filing to a broader unclassified population if finalized.

What is the 5 percent threshold on the SF-328? Question 1 asks whether any foreign person directly or indirectly owns, beneficially owns, or subscribes to 5 percent or more of your shares, participation interests, units, or total capital commitment. A separate threshold in Question 7 covers revenue, net income, tuition, gifts, and endowments: 5 percent from any single foreign person or 15 percent in aggregate. Affirmative answers require supporting documentation, not just a check mark.

Is the May 2026 Section 847 FOCI rule in effect? No. It was published as a proposed DFARS rule on May 7, 2026 and remains a proposal as of August 18, 2026. Describe every element of it conditionally until a final rule publishes.

Is $5 million the CMMC threshold? No. The $5 million figure belongs to the proposed FOCI and beneficial-ownership rule, not to CMMC. CMMC applicability runs on the solicitation, the clause, the information handled, the implementation phase, and the micro-purchase threshold.

Did the CMMC suspension change anything specific to foreign-owned companies? No. Phase I began November 10, 2025 and was originally scheduled through November 9, 2026. The July 13, 2026 suspension stopped the transition to Phase II and later milestones; it did not create a foreign-company exception. During the review, program managers may designate Level 1 (Self) or Level 2 (Self) and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). DFARS 252.204-7012 remains in force, and SPRS and affirmation duties remain where the applicable clauses require them.


The bottom line

You are not disqualified. That is the finding, it comes from the rule text rather than from anyone's opinion, and it is the part most worth carrying into your next leadership meeting.

What you have is a mapping problem with a known answer. Five gates, separate authorities, and one sequence that works:

  1. Find the written requirement — the clause, the level, the assessment type, in the contract.
  2. Separate the information — FCI, CUI with its categories and markings, classified information, and export-controlled status. These labels can overlap, but they trigger different handling questions.
  3. Map ownership and access — the entity chart, the governance rights, the parent services, and every privileged path into your environment.
  4. Identify which gate is blocking the next expensive decision. Start there.
  5. Hire the category that can resolve that gate — and only then move to architecture and assessment.

Do that in order and this becomes a project. Do it out of order and it becomes two projects, because the second one pays to undo the first.

Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path →

The result maps you to a provider category — not a ranked, endorsed, or government-approved company.

Do not submit CUI, classified information, drawings, source code, export-controlled technical data, contract attachments, SSPs, POA&Ms, network diagrams, credentials, or sensitive ownership documents.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.

Independence: The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCSA, DCMA DIBCAC, NIST, or any U.S. government agency.

Last verified: August 18, 2026 · Report a correction